This article may contain affiliate links. We may earn a small commission at no extra cost to you if you make a purchase through these links.
Federal AI Preemption vs State AI Laws: Where It Stands
Trump's AI order can't erase state laws on its own. Here's which state AI laws apply to builders in fall 2026, and what the federal push has changed.

An executive order cannot erase a state statute on its own; that takes an act of Congress or a court ruling. So as of September 2026, the state AI laws that builders must plan around are still on the books: Texas's TRAIGA and California's frontier-model transparency law have applied since January 1, 2026, and New York's rewritten RAISE Act and Colorado's slimmed-down replacement law both take effect January 1, 2027. What the federal campaign has changed so far is the shape of those laws, not whether they exist.
That distinction matters for anyone shipping AI products in the US. The White House has built a three-part pressure system: an executive order that sets up a Justice Department litigation unit and ties federal money to state behavior, a legislative framework asking Congress to preempt state rules on AI development, and the Justice Department joining a lawsuit against the most aggressive state law. The clearest result is in Colorado, which rewrote its law under that pressure. The other laws are intact. This guide lays out what each federal lever actually does, which state laws apply to you, and how to build a compliance plan that holds up however the fight ends.
What does Executive Order 14365 actually do?
President Trump signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence," on December 11, 2025; it was published in the Federal Register on December 16, 2025. It creates no new rules for AI companies. Instead, it directs agencies to challenge, defund, or displace state rules. The order names one state law as an example: it says "a new Colorado law banning 'algorithmic discrimination' may even force AI models to produce false results."
| Section | Who acts | What the order directs | Deadline in the order |
|---|---|---|---|
| Sec. 3 | Attorney General | Create an AI Litigation Task Force to challenge state AI laws that conflict with the order's policy, including on interstate-commerce grounds | 30 days |
| Sec. 4 | Secretary of Commerce | Publish an evaluation of state AI laws, flagging those that require models to alter truthful outputs or compel disclosures that may violate the Constitution | 90 days |
| Sec. 5 | Commerce / agencies | Make states with "onerous" AI laws ineligible for BEAD broadband non-deployment funds; let agencies condition discretionary grants on states not enforcing conflicting AI laws | 90 days |
| Sec. 6 | FCC Chairman | Start a proceeding on a federal AI reporting and disclosure standard that would preempt conflicting state laws | 90 days after the Commerce evaluation is published |
| Sec. 7 | FTC Chairman | Issue a policy statement on how federal deception law applies to AI models, and when state laws requiring altered outputs are preempted | 90 days |
| Sec. 8 | White House AI and science advisers | Prepare a legislative recommendation for a uniform federal framework, without preempting state child-safety, AI infrastructure, or state-procurement laws | Not time-bound |
The Justice Department met the first deadline. A department memorandum titled "Artificial Intelligence Litigation Task Force," posted on justice.gov, is dated January 9, 2026. The rest of the order depends on agencies acting under authority Congress gave them for other purposes. That is why the legal community treats the order as the start of a fight rather than the end of state regulation. A Commerce evaluation can name a law "onerous" but cannot void it. An FCC or FTC preemption claim would be tested in court on whether the agency has that power at all.
What does the White House want Congress to preempt?
The executive branch's real goal is a statute. In March 2026 the White House published its National Policy Framework for Artificial Intelligence legislative recommendations. The final section asks Congress to "preempt state AI laws that impose undue burdens to ensure a minimally burdensome national standard consistent with these recommendations, not fifty discordant ones."
Three lines in that section tell builders more than the rest of the document:
- "States should not be permitted to regulate AI development, because it is an inherently interstate phenomenon with key foreign policy and national security implications." This goes straight at the laws that regulate model developers, which today means California's SB 53 and New York's RAISE Act.
- "States should not unduly burden Americans' use of AI for activity that would be lawful if performed without AI." This is the argument against AI-specific rules for hiring, lending and other decisions, the territory Colorado's original law covered.
- "States should not be permitted to penalize AI developers for a third party's unlawful conduct involving their models." In effect, a liability shield for developers over what customers do with their models.
The framework also lists what a federal standard should leave to states: the "traditional police powers" to enforce generally applicable laws against AI developers and users, "including particular laws to protect children, prevent fraud, and protect consumers"; state zoning over where AI infrastructure goes; and rules governing a state's own use of AI. It also recommends that Congress "not create any new federal rulemaking body to regulate AI," and leave regulation to existing agencies and industry-led standards.
The so-what: the carve-outs are broad. Even if Congress passed this framework word for word, a state attorney general could still bring a consumer-protection or anti-fraud case against an AI product under general law. Preemption along these lines would remove AI-specific rules for developers, not state enforcement against AI companies generally.
What happened in Colorado, the first test case?
Colorado shows how the federal campaign works in practice. The sequence, from the state legislature's own records and the Justice Department:
- May 17, 2024: Governor Jared Polis signs SB24-205, requiring developers and deployers of "high-risk" AI systems to use reasonable care against "algorithmic discrimination" starting February 1, 2026, with impact assessments and attorney-general reporting.
- August 28, 2025: Polis signs SB25B-004, passed in a special session, which pushes the start date to June 30, 2026.
- December 11, 2025: Executive Order 14365 singles out the Colorado law by name.
- April 9, 2026: xAI sues to block the law.
- April 24, 2026: The Justice Department intervenes, arguing the law violates the Fourteenth Amendment's Equal Protection Clause by requiring companies to prevent unintentional disparate impact based on race and sex.
- April 27, 2026: According to a McDermott Will & Schulte analysis, a federal magistrate judge enters a stipulated order under which Colorado's attorney general agrees not to enforce SB24-205 until 14 days after the court rules on xAI's preliminary-injunction motion, and xAI holds off on that motion until replacement legislation is adopted.
- May 14, 2026: Polis signs SB26-189, which repeals and reenacts the framework as a narrower law on "automated decision-making technology," effective January 1, 2027.
The replacement law is a different kind of law. Developers must give deployers technical documentation covering intended uses, categories of training data and known limitations, and keep records for at least three years. Deployers must give consumers "clear and conspicuous notice" when automated decision-making technology is used and, within 30 days of an adverse outcome, a plain-language description of the technology's role. Consumers get a right to correct their data and to "meaningful human review and reconsideration." The attorney general enforces it through the Colorado Consumer Protection Act, with a 60-day cure period before January 1, 2030. McDermott's analysis says the affirmative algorithmic-discrimination duty was removed, leaving a notice-and-disclosure regime; the legislature's summary notes the law also sets how fault is split between developers and deployers in discrimination suits brought under existing law.
Our read: no court ruled on whether Colorado's original law was constitutional. The litigation created leverage, and the legislature did the rest. That is the template to expect elsewhere, because it avoids a precedent either side might lose. McDermott also reports that xAI and the Justice Department are expected to challenge SB26-189, so treat the replacement law as likely but not certain to stick.
Which state AI laws are in force, and when?
Four state laws define the US map for most builders as of September 2026. Two already apply; two start on January 1, 2027.
| Law | Who it covers | Core obligation | Effective | Enforcement |
|---|---|---|---|---|
| California SB 53, Transparency in Frontier Artificial Intelligence Act | Developers training models above 1026 operations; heavier duties for those with annual revenue over $500 million | All frontier developers publish transparency reports and report critical safety incidents to the Office of Emergency Services within 15 days (24 hours, to appropriate authorities, if there is imminent risk of death or serious injury); large developers must also publish a frontier AI framework; whistleblower protections | January 1, 2026 | Attorney General; up to $1,000,000 per violation |
| Texas HB 149, Responsible Artificial Intelligence Governance Act | Anyone who does business in Texas; some sections apply only to government agencies | Bans developing or deploying AI with intent to incite self-harm or crime, unlawfully discriminate, or produce child sexual abuse material; disclosure duties for agencies and health care providers | January 1, 2026 | Attorney General only, 60-day cure; $10,000 to $200,000 per violation depending on type |
| New York S8828, rewritten RAISE Act | Frontier developers (above 1026 operations); extra duties at $500 million-plus revenue | All frontier developers: transparency reports and critical safety incident reports within 72 hours (24 hours for imminent threats). Large developers also: a frontier AI framework and disclosure statements filed with a new Department of Financial Services office | January 1, 2027 | Up to $1 million for a first violation and $3 million for subsequent ones |
| Colorado SB26-189, automated decision-making technology | Developers and deployers of covered decision-making systems | Documentation to deployers, consumer notice, adverse-decision explanations within 30 days, human review on request | January 1, 2027 | Attorney General under the Consumer Protection Act; 60-day cure until 2030 |
Sources: California SB 53 text (chaptered September 29, 2025); Texas HB 149 (signed June 22, 2025); New York S8828 (signed March 27, 2026, Chapter 96); Colorado SB26-189 as linked above.
Why are frontier transparency laws a harder federal target?
The federal argument against Colorado's original law was that it forced outcomes: prevent disparate impact, or face liability. The Justice Department framed that as compelled race- and sex-conscious behavior. California's SB 53 and New York's RAISE Act are built differently. They mostly require developers to write down and publish what they already say they do about catastrophic risk, and to report serious incidents. Large labs already publish long safety documents voluntarily, such as Anthropic's system card for Claude Mythos Preview, so the added burden is harder to paint as onerous.
The executive order anticipates this with a different theory. Section 4 asks Commerce to flag state laws that compel developers to disclose information in ways that may violate the First Amendment. The framework adds the broader claim that model development is inherently interstate and belongs to Washington. Both are arguable, and neither has been tested in a ruling on these laws. Our assessment: absent an act of Congress, disclosure-and-reporting laws are the most likely to survive, and the two frontier laws have already converged on the same thresholds (1026 operations and $500 million in revenue), which weakens the "fifty discordant" argument.
The thresholds also mean most companies are not frontier developers at all. A startup fine-tuning or deploying other developers' models is generally outside SB 53 and RAISE. That includes deploying open-weight models such as those covered in our open-source LLM landscape. For those teams, the laws that matter are Texas's intent-based bans, Colorado's notice rules if they make consequential decisions about consumers, and general consumer-protection law, which every version of the federal proposal leaves with the states.
What should builders do this fall?
- Classify yourself against the thresholds. Are you a frontier developer (above 1026 training operations)? Do you exceed $500 million in revenue? Do you deploy systems that make consequential decisions about Colorado consumers? Do you do business in Texas? The answers decide which of the four laws apply.
- Build one incident process for the strictest clock. If you are a frontier developer, New York's 72-hour reporting window is tighter than California's 15 days, and both have a 24-hour track for imminent harm. Design to the shortest timeline and you meet both.
- Write intended-use documentation now. Texas's prohibitions turn on intent, and Colorado's replacement law requires developers to hand deployers intended uses, training-data categories and known limitations. The same document serves both, and it is the evidence you would want in any state enforcement action.
- Stage Colorado notices for January 1, 2027. Consumer notice, 30-day adverse-decision explanations and a human-review path need product work, not just legal review. Budget it as if the law will take effect, since the stipulated pause covered the old statute, not the new one.
- Do not bet your roadmap on preemption. The BEAD funding lever pressures state governments, not companies. Agency preemption faces court challenges, and the framework's carve-outs keep state consumer-protection and fraud enforcement alive even in the best case for industry.
What should you watch next?
Four signals will tell you whether the map changes in 2027. First, whether a preemption bill based on the White House framework moves in Congress, and whether its text keeps the "no state regulation of AI development" language. Second, the FCC proceeding and FTC policy statement the order calls for, which would be the first attempts to claim preemptive effect through agency action. Third, the next phase of the Colorado litigation, including any challenge to SB26-189. Fourth, whether the Commerce evaluation or any Justice Department filing names California's or New York's frontier laws. Until one of those moves, the state laws in the table above are the law.
Frequently Asked Questions
Does Executive Order 14365 preempt state AI laws?
No. The order does not invalidate any state law by itself. It directs the Justice Department to challenge state laws in court, asks Commerce to identify "onerous" laws, ties some federal broadband and grant funding to state behavior, and asks the FCC and FTC to act. Actual preemption requires an act of Congress or a court ruling, and any agency attempt would face legal challenge.
Is the Colorado AI Act still happening?
Not in its original form. Colorado replaced SB24-205 with SB26-189, signed May 14, 2026, which, according to a McDermott Will & Schulte analysis, replaces the affirmative algorithmic-discrimination duty with documentation, consumer notice, adverse-decision explanations and human review. The new law takes effect January 1, 2027, and is enforced by the attorney general, with a 60-day cure period until 2030. Further legal challenges are expected.
Does California's SB 53 apply to my startup?
Probably not, unless you train frontier models. SB 53 covers developers that trained a model using more than 1026 integer or floating-point operations, with the heaviest duties on those with annual revenue above $500 million. Companies that fine-tune, deploy or build on other developers' models are generally outside its scope, though California's general consumer-protection laws still apply to them.
What would a federal preemption law leave to the states?
Under the White House's March 2026 framework, states would keep their police powers to enforce generally applicable laws against AI developers and users, including child-protection, anti-fraud and consumer-protection laws, plus zoning over AI infrastructure and rules for their own use of AI. What they would lose is the ability to regulate AI development itself, or to penalize developers for third parties' misuse of their models.
Enjoying this article?
Get more strategic intelligence delivered to your inbox weekly.
Enjoyed this article?
VentureBeast.Tech is independent and reader-supported. If this saved you time, you can buy us a coffee — it keeps the research deep and the site ad-light.
Support us on Ko-fi


Comments (0)
No comments yet. Be the first to share your thoughts!